Weird result when comparing Suricata detections with snort (using same traffic) - what am I missing?

Hello Victor,

Thanks for weighing in.

That was internal prod traffic that I cannot share. Those vars are all set the same, the main difference in config is on the networking side (pfring vs af_packet and related tuning).